• Sources: preprint
  • Summary: Lifecycle hooks bind shell commands to runtime events such as session start, tool calls and file edits, run with host privileges, and can fire at times the model never observes. Under a threat model where the attacker controls only plugin metadata and hook configuration, a benign versioned plugin is trojanized by an update alone. Across 25 harness and backend combinations in 1,000 runs the authors report compromising all seven harnesses, with per-harness success up to 92.5 percent, Microsoft Defender at 0 percent recall, and three static defenses together missing 47.5 percent of malicious artifacts. Preprint posted 2026-09-03 and not peer reviewed.
  • Why it matters: Installing an agent plugin means trusting an update channel that no review step covers.

send feedback on this story